# Your address with Tailscale

You already have a temporary address; this makes it permanent.

At the end, the runner has an address like `https://loopgate-runner.your-tailnet.ts.net` that only your team's own laptops can open: Tailscale builds a private network between your devices, called a tailnet, and nothing outside it can reach the runner.

## At a glance

**Time:** 15 minutes, plus a few minutes on each teammate's laptop.

**What you need:**

- The runner, started in [Any Linux computer with Docker](any-box.md)
- A Tailscale account (check Tailscale's pricing for the size of your team)
- Tailscale on the laptop of each person who opens the runner

**Steps:**

1. Put Tailscale on the box
2. Turn on HTTPS once
3. Serve the runner
4. Let your team in

## Steps

1. **On the box, install Tailscale with its own script.**

   ```sh
   curl -fsSL https://tailscale.com/install.sh | sh
   ```

   You should see: `Installation complete!` and a hint to run `tailscale up`.

2. **Join the box to your tailnet.**

   ```sh
   sudo tailscale up
   ```

   You should see: `To authenticate, visit:` and a web address. Open it on your laptop, sign in to Tailscale and approve the box; the command on the box then finishes.

3. **On your laptop, open the admin console at `https://login.tailscale.com/admin/dns`** and check that **MagicDNS** is enabled.

   > MagicDNS gives each device a name; it is on for most new tailnets.

4. **Scroll to HTTPS Certificates, press Enable HTTPS and confirm.**

   You should see: HTTPS Certificates marked as enabled.

   > It is off until an admin turns it on. This was the step we missed ourselves.

5. **On the box, send the tailnet's HTTPS traffic to the runner.**

   ```sh
   sudo tailscale serve --bg 4311
   ```

   You should see: `Available within your tailnet:` followed by an address ending `.ts.net/`. That is the runner's address; copy it.

6. **Give the runner that address**, with no slash at the end, and restart it.

   ```sh
   cd ~/loopgate && echo "LOOPGATE_RUNNER_URL=https://loopgate-runner.your-tailnet.ts.net" >> runner.env
   docker compose up -d runner
   ```

   You should see: the portal's Devices row shows the new address, no longer marked `temporary`.

7. **In the admin console, open Users and invite each teammate.**

8. **Each teammate installs Tailscale from `https://tailscale.com/download`** and signs in to your tailnet.

   You should see: the box `loopgate-runner` in their Tailscale device list.

9. **Each teammate opens the Loopgate portal, opens Devices and presses Open** on the runner's row.

   You should see: the workbench. The very first visit may take a few seconds while Tailscale makes the certificate.

   > Their browser then stays signed in for thirty days from its last use, while Tailscale is on.

## Check

The runner names its `.ts.net` address, and Settings → General no longer says `temporary`:

```sh
cd ~/loopgate && docker compose logs runner
```

You should see: `Runner ready at https://…ts.net`.

## Next

[Connect Slack](slack.md), if you have not yet. Links it posts from now on survive a restart.

## If something is off

- **The address does not open.** Check that Tailscale is on and signed in to your tailnet on that laptop.
- **`tailscale serve` says HTTPS is not enabled.** Turn on HTTPS Certificates (step 4), then run step 5 again.
- **"This link expired. Open the runner from the portal again."** Press **Open** in **Devices** again.

## Doing it by hand

[By hand](by-hand.md) has every line of `runner.env` and `tunnel.env`.
